Storm-2372 is a nation-state threat actor that was among the first to use device code phishing in the wild, starting in 2024. Their campaigns demonstrated the effectiveness of this technique for stealing access tokens and bypassing MFA, paving the way for broader criminal adoption.